Cybersecurity Network Engineer
Job Description
Seminole Hard Rock Support Services provides a comprehensive benefits package designed to support health and well-being, planning for the future, and maintaining a healthy work-life balance. Benefits may vary with employment status. The Network Cybersecurity Engineer role is onsite in Davie, FL and focuses on building measurable, automated network security outcomes across on-premises and major cloud environments.
What you’ll do
Implement, operate, and continuously improve enterprise network security controls that defend traffic across on-premises and cloud, with Microsoft Azure as the primary platform (and additional coverage across AWS and Google Cloud). You will turn architecture and policy into defenses that can be deployed, tuned, instrumented, and validated with telemetry for detection, triage, and response.
- Deploy, configure, and tune secure-access service edge controls including secure web gateway, cloud firewall, CASB, and DLP policy to keep coverage current
- Operate zero-trust network access for workforce and third parties, moving away from legacy VPN patterns toward identity-aware, least-privilege application access
- Administer an enterprise browser approach to enforce least-privilege, isolated access to sensitive applications from both managed and unmanaged endpoints
- Tune SSL/TLS inspection, tenant restrictions, and egress policy, including traffic types sensitive to interception such as NTLM, Kerberos, and certificate-pinned traffic
- Manage traffic steering, forwarding, and PAC configurations so users route to the correct control path from locations worldwide
- Operate edge and perimeter defenses including WAF rules, DDoS mitigation, bot management, and CDN and DNS policy
- Run and harden API security posture and runtime protection, discovering shadow APIs and closing authentication and data exposure gaps
- Administer next-generation firewall policy, NAT, and rule lifecycle across data center and property perimeters to drive rule hygiene
- Harden edge DNS, certificate, and TLS posture in partnership with PKI and infrastructure teams
- Coordinate perimeter changes across franchise, property, and vendor networks so remote sites integrate securely without breaking authentication or application flows
- Deploy and tune network detection and response, triaging anomalous east-west and north-south activity and producing high-fidelity findings for the SOC
- Engineer network telemetry pipelines (flow data, DNS logs, proxy logs, firewall logs, packet metadata) to route, shape, and enrich data for cost-effective analysis
- Develop and tune network-focused detections and SIEM content, mapping coverage to attacker techniques
- Investigate network-layer incidents end-to-end with packet capture and log correlation, isolating root cause under time pressure
- Maintain authoritative visibility of network assets and attack surface by reconciling what is connected against what is inventoried
- Apply zero-trust segmentation and least-privilege access across campus, data center, gaming, and hospitality network estates
- Design and enforce microsegmentation and network policy for sensitive zones (payment, gaming, surveillance, OT/IoT) with infrastructure and compliance teams
- Implement cloud network security guardrails across Azure (primary), plus AWS and Google Cloud: virtual network design, firewalling, private connectivity, and logging baselines (including Azure Firewall, NSGs, Private Link)
- Remediate cloud network misconfigurations and exposure paths surfaced by posture management to prevent drift
- Integrate network security checks into infrastructure-as-code and deployment workflows so network changes are secure by default
- Build network security automations, integrations, and response playbooks using APIs and SOAR
- Leverage AI/ML and large language models to analyze network telemetry, accelerate alert triage and enrichment, surface anomalies, and automate reporting/documentation
- Develop production-grade scripts, services, and tooling using Python, PowerShell, and Go to operationalize controls and reduce repetitive manual work
- Automate firewall rule reviews, policy validation, and configuration compliance checks so drift is caught by pipelines
- Instrument metrics and dashboards to measure network control coverage, detection efficacy, and remediation timeliness
- Support Cybersecurity Strategy & Governance, audit, and privacy programs by automating evidence collection and continuous control monitoring for network controls
- Document standards, runbooks, integration designs, and operating procedures for repeatable network control operations
- Research, prototype, and pilot emerging network security tools and AI-driven capabilities to improve detection and automation
- Participate in an on-call rotation and incident response for a 24/7 gaming and hospitality environment
What you bring
- 5–7+ years combined experience in network engineering, network security engineering, or cloud networking, with at least 4+ years hands-on network security engineering in enterprise environments
- Deep network engineering expertise: routing and switching, firewalls, proxies, VPN/ZTNA, load balancing, DNS, TLS/PKI
- Strong automation and software proficiency with hands-on experience in Python, PowerShell, Go, or similar languages; ability to build custom security tooling, integrations, and automation
- Practical experience applying AI/ML or large language models to network data analysis, detection, triage, or automation
- Working knowledge of SASE/SSE platforms including secure web gateway, ZTNA, CASB, and DLP; plus WAF and DDoS mitigation, NDR, and API security
- Hands-on cloud network security experience on Microsoft Azure (required), and working experience in AWS and/or Google Cloud including virtual network design, cloud firewalls, private connectivity, and posture management
- Solid fundamentals: TCP/IP, BGP/OSPF, DNS, DHCP, TLS/PKI, NAT, IPv6, packet analysis, segmentation, and zero-trust access models
- Experience integrating network security tools and data sources via API, with familiarity in SOAR playbook development and SIEM content engineering
- Familiarity with gaming and hospitality compliance frameworks (e.g., PCI-DSS, SOX, tribal gaming regulations, GLBA) is preferred but not required
- Certifications preferred: Cisco CCNP Security, vendor certifications in next-gen firewalls and SASE/SSE, Microsoft AZ-700 or AZ-500, AWS Advanced Networking Specialty, GIAC (GCIA, GDSA, GCLD); CISSP is a plus
Security and automation capabilities you’ll use
- Microsoft Azure (primary), AWS, Google Cloud; cloud network security components such as Azure Firewall, NSGs, and Private Link
- SASE: SWG, ZTNA, CASB, DLP
- Edge and application security: WAF, DDoS mitigation, bot management, CDN, DNS
- API security and runtime protection
- Visibility and detection: network detection and response using flow and packet analysis, plus SIEM and SOAR
- PKI and TLS: SSL/TLS inspection, PKI, certificate lifecycle, and secrets management
- Languages and tooling: Python, PowerShell, Go
- Zero-trust and segmentation: microsegmentation and least-privilege access
- AI/ML and large language models for telemetry analysis and automation